7.5
CVE-2020-8286
- EPSS 0.28%
- Published 14.12.2020 20:15:14
- Last modified 21.11.2024 05:38:39
- Source support@hackerone.com
- Teams watchlist Login
- Open Login
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
Data is provided by the National Vulnerability Database (NVD)
Fedoraproject ≫ Fedora Version32
Fedoraproject ≫ Fedora Version33
Debian ≫ Debian Linux Version9.0
Debian ≫ Debian Linux Version10.0
Netapp ≫ Clustered Data Ontap Version-
Netapp ≫ Hci Management Node Version-
Netapp ≫ Hci Bootstrap Os Version-
Netapp ≫ Hci Storage Node Firmware Version-
Siemens ≫ Simatic Tim 1531 Irc Firmware Version <= 2.2
Siemens ≫ Sinec Infrastructure Network Services Version < 1.0.1.1
Oracle ≫ Communications Billing And Revenue Management Version12.0.0.3.0
Oracle ≫ Communications Cloud Native Core Policy Version1.14.0
Oracle ≫ Peoplesoft Enterprise Peopletools Version8.58
Splunk ≫ Universal Forwarder Version >= 8.2.0 < 8.2.12
Splunk ≫ Universal Forwarder Version >= 9.0.0 < 9.0.6
Splunk ≫ Universal Forwarder Version9.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.28% | 0.514 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.